First published: Wed Dec 31 2003(Updated: )
Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winamp iPod Plugin | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1272 is classified as a high severity vulnerability due to its potential to allow remote code execution and cause denial of service.
To mitigate CVE-2003-1272, you should upgrade to a newer version of Winamp that does not have this vulnerability.
CVE-2003-1272 enables remote attackers to execute arbitrary code or crash the application via crafted .b4s files.
CVE-2003-1272 affects Winamp version 3.0.
While CVE-2003-1272 primarily causes denial of service, it may indirectly lead to data loss if the application crashes while accessing files.